Search
12,997 CVEs
CVEs (12,997, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 12,997 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61539 | CRITICAL | Patched | 10.0 | 2026-08-21 | Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output t… |
| CVE-2026-69502 | CRITICAL | 10.0 | 2026-08-21 | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-69555 | CRITICAL | 10.0 | 2026-08-20 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-69836 | CRITICAL | 10.0 | 2026-08-20 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-65816 | CRITICAL | 10.0 | 2026-08-20 | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-65801 | CRITICAL | 10.0 | 2026-08-20 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-65770 | CRITICAL | 10.0 | 2026-08-20 | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute… | |
| CVE-2026-22306 | CRITICAL | Patched | 10.0 | 2026-08-19 | Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Oz… |
| CVE-2026-20357 | CRITICAL | 10.0 | 2026-08-19 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review… | |
| CVE-2026-20358 | CRITICAL | 10.0 | 2026-08-19 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review… | |
| CVE-2026-20315 | CRITICAL | 10.0 | 2026-08-19 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20317 | CRITICAL | 10.0 | 2026-08-19 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20030 | CRITICAL | 10.0 | 2026-08-19 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review… | |
| CVE-2026-75949 | NONE | — | 2026-08-19 | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_pat… | |
| CVE-2026-74803 | NONE | — | 2026-08-19 | Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type fa… | |
| CVE-2026-67364 | NONE | — | 2026-08-19 | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The… | |
| CVE-2026-18051 | CRITICAL | Patched | 10.0 | 2026-08-19 | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write… |
| CVE-2026-76008 | CRITICAL | 10.0 | 2026-08-19 | A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This … | |
| CVE-2026-70921 | CRITICAL | 10.0 | 2026-08-18 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easil… | |
| CVE-2026-70880 | CRITICAL | 10.0 | 2026-08-18 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 1… | |
| CVE-2026-61241 | CRITICAL | 10.0 | 2026-08-18 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 1… | |
| CVE-2026-75784 | CRITICAL | 10.0 | 2026-08-18 | A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP H… | |
| CVE-2026-73343 | CRITICAL | 10.0 | 2026-08-18 | Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | |
| CVE-2026-75874 | CRITICAL | Patched | 10.0 | 2026-08-18 | Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 15… |
| CVE-2026-74253 | NONE | Patched | — | 2026-08-17 | Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {sou… |